Latest CVE Feed
-
5.4
MEDIUMCVE-2018-12672
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper authorization was implemented, this vulnerability could be leveraged to per... Read more
Affected Products : h.264_poe_ip_camera_firmware sv-b01poe-1080p-l sv-b11vpoe-1080p-l sv-d02poe-1080p-l- EPSS Score: %0.21
- Published: Oct. 19, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-18475
Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malicious script into the header field of the outbox and sends it to other users. When other users open the email, the malicious code w... Read more
Affected Products : hucart- EPSS Score: %0.17
- Published: Aug. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-20903
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.... Read more
Affected Products : editor-core- EPSS Score: %0.42
- Published: Oct. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19286
A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the source field of the editor.... Read more
Affected Products : jeesns- EPSS Score: %0.19
- Published: Sep. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-20781
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.... Read more
Affected Products : ucms- EPSS Score: %0.26
- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18600
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.... Read more
Affected Products : formcraft- EPSS Score: %0.18
- Published: Sep. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-7492
Cross-site scripting (XSS) vulnerability in Reference Data Management (RDM) in IBM InfoSphere Master Data Management 10.1, 11.0 before FP5, 11.3, 11.4, and 11.5 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a craf... Read more
- EPSS Score: %0.17
- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-3413
All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked.... Read more
- EPSS Score: %0.16
- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2264
Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.... Read more
Affected Products : custom_job_icon- EPSS Score: %0.23
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23185
A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : php-fusion- EPSS Score: %0.27
- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23370
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.... Read more
Affected Products : yzmcms- EPSS Score: %0.13
- Published: May. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4431
IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
- EPSS Score: %0.24
- Published: Feb. 12, 2020
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2016-3567
Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.3, 8.4, 15.1, 15.2, and 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related... Read more
Affected Products : primavera_p6_enterprise_project_portfolio_management- EPSS Score: %0.23
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-15968
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management inte... Read more
- EPSS Score: %0.29
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25392
A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Article' field under the 'Article' plugin.... Read more
Affected Products : csz_cms- EPSS Score: %0.19
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-2092
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.24
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2019-6577
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP... Read more
Affected Products : simatic_wincc_\(tia_portal\) simatic_wincc_runtime simatic_wincc_runtime_advanced simatic_hmi_comfort_panels_firmware simatic_hmi_comfort_outdoor_panels_firmware simatic_hmi_ktp_mobile_panels_ktp400f_firmware simatic_hmi_ktp_mobile_panels_ktp700_firmware simatic_hmi_ktp_mobile_panels_ktp700f_firmware simatic_hmi_ktp_mobile_panels_ktp900_firmware simatic_hmi_ktp_mobile_panels_ktp900f_firmware +13 more products- EPSS Score: %0.38
- Published: May. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-6653
There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles.... Read more
Affected Products : big-iq_centralized_management- EPSS Score: %0.25
- Published: Sep. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-18636
A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter.... Read more
Affected Products : .net_forum- EPSS Score: %0.24
- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19085
A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.... Read more
Affected Products : server- EPSS Score: %0.21
- Published: Nov. 18, 2019
- Modified: Nov. 21, 2024